Malicious PDF — malware analysis report

Static analysis result for SHA-256 9f3336675b123095…

MALICIOUS

PDF

36.4 KB Created: 2021-06-30 07:19:28 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: b5cb5274f0d68586788ae67bdafbba31 SHA-1: 6bf61d321c2cfa814f991d7149f20d7a6e20e35a SHA-256: 9f3336675b123095680e13c427ea6878f066eb09894dc84f2909452f3d0b242a
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains numerous embedded URLs that form a link farm, likely intended to direct users to malicious content or phishing sites. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, and the ML classifier strongly suggests malicious intent. The document body, though partially corrupted, contains references to game cheats and a URL that likely serves as a download or redirection point.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/roblox-the-legendary-swords-rpg-cheats-game-hack
    • https://www.dahu-villa.com.tw/upload/files/roblox-tracker_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/pokemon-go-free-qr-code_GM1094591345.pdf
    • https://www.dahu-villa.com.tw/upload/files/do-you-get-windows-10-minecraft-for-free-with-java_GM479516143.pdf
    • https://www.dahu-villa.com.tw/upload/files/how-do-i-get-free-robux_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/free-robux-live_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/wurst-hacked-client-112-2_GM479516143.pdf
    • https://www.dahu-villa.com.tw/upload/files/coin-master-free-daily-spins_GM406889139.pdf
    • https://www.dahu-villa.com.tw/upload/files/roblox-drama-class-cheat-sheet_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/how-to-get-400-robux-on-roblox-for-free-2021_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/free-roblox-lua-executor_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/free-robux-gift-card-codes-2021-november_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/robux-generator-without-human-verification_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/what-is-the-speed-hack-code-on-roblox_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/how-to-download-minecraft-hacks_GM479516143.pdf
    • https://www.dahu-villa.com.tw/upload/files/how-to-get-free-robux-on-roblox-on-an-ipad_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/robux-hack-no-survey_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/how-to-hack-to-get-robux_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/coin-master-email-free-spins_GM406889139.pdf
    • https://www.dahu-villa.com.tw/upload/files/roblox-online-free-no-download_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/coin-master-unlimited-spin-hack-mod-apk_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003536.bin
6419afc3ddaab50cd55de1b9546a1c5bd4c1d38d0ab0b9bcd1ff75732a5917b0
pdf-font-stream PDF embedded font (sfnt) at offset 0x3536 22564 bytes
font_01_sfnt_off000067e0.bin
785662cc8235ec75214b206bf58cbe19448faf2005e2ebd4ccd69346794dda29
pdf-font-stream PDF embedded font (sfnt) at offset 0x67E0 19448 bytes